Free Cyber Advisor sessions work, but too few small firms know to ask
Roughly one in five small organizations that approached the NCSC’s free Cyber Advisor scheme have since certified, on the agency’s figures. But a scheme that waits to be asked will reach few of the UK’s 5.64 million small businesses

- The NCSC’s free 30-minute consultation puts small firms in front of an NCSC-assured Cyber Advisor, and it is turning inquiries into certificates.
- Official data shows low awareness of Cyber Essentials and few businesses checking the cyber risks of their suppliers.
- Security teams can raise take-up by pairing every Cyber Essentials request to small suppliers with the free consultation route.
The National Cyber Security Centre (NCSC) said on 15 July that more than 760 small organizations across the UK have reached out to it since the option of a free 30-minute consultation with one of its Cyber Advisors was introduced. Well over 150 of them have already gained Cyber Essentials certification through that route, with more under way. The figures appeared in a blog post by the NCSC’s head of Cyber Essentials and Cyber Advisor.
Cyber Advisors are consultants assured by the NCSC to work specifically with smaller organizations. The scheme started in 2023. The free half-hour is an introduction to Cyber Essentials, the government’s baseline for cybersecurity.
Turning roughly one in five of those inquiries into a certificate is a strong result for small-business outreach. The difficulty is the number underneath it.
The scheme shows what works with small firms: a named, vetted person, a short conversation and a clear next step. But it depends on small businesses finding it, and most will not go looking. The people best placed to send them are not in government. They are the larger customers small firms already answer to.
The numbers are pilot-sized
The Department for Business and Trade’s business population estimates counted 5.64 million small businesses, with up to 49 employees, at the start of 2025. Set against that population, even several thousand consultations a year would touch a small fraction of firms.
The government’s own Cyber Security Breaches Survey 2025/2026, published on 30 April, shows the gap. When prompted, 17% of businesses were aware of Cyber Essentials. Just 5% said they held it, up from 3% the year before, although the share among small businesses rose more sharply, from 5% to 12%. Meanwhile 46% of small businesses and 65% of medium ones reported a breach or attack in the previous 12 months.
The same survey found small businesses slipping on basics they had improved the year before. The share carrying out cybersecurity risk assessments fell from 48% to 41%, and the share with business continuity plans covering cyber fell from 53% to 44%.
Against those numbers, more than 760 inquiries show that the model works but say little about its reach.
Demand has to be pulled
The NCSC is candid about why. Its post says “many smaller organisations believe that cyber security is too complicated, too expensive, and doesn’t address the real-world risks that small businesses face.” A free consultation answers the first objection. It only partly answers the second, because the free half-hour is only an introduction. And no campaign answers the third on its own.
What moves a small firm is usually a request from someone it depends on. The breaches survey suggests that pressure is thin. Only 15% of businesses said they reviewed the cyber risks posed by their immediate suppliers. Among medium businesses the figure was 30%, and among large businesses 48%.
That leaves most medium-sized businesses, and around half of large ones, not formally reviewing the cyber risks their immediate suppliers pose.
Security teams can close the gap
For CISOs and security teams with long tails of small suppliers, the NCSC has built something they can use at no cost to themselves. Three changes would put it to work.
First, pair every request with a route. A supplier asked to hold Cyber Essentials should get, in the same message, a link to the free Cyber Advisor consultation. A requirement with no starting point reads as a reason to drop the contract.
Second, accept progress. A small supplier that has had its consultation and is working through the five steps of Cyber Essentials with an assured advisor is a lower risk than one that has done nothing. Supplier reviews can record that stage rather than treating certification as pass or fail.
Third, point to the other free tools. The NCSC’s Early Warning service alerts organizations to potential threats on their networks, and its Cyber Action Toolkit offers small firms a structured path toward Cyber Essentials. Neither costs the supplier anything.
None of this replaces the scheme’s own outreach. It adds the one thing a government blog cannot supply: a customer asking.
The NCSC has built a front door that small firms walk through. The task now is sending more of them to it.
Get The VETTDD BriefingThe week in the technology channel, every week.
Subscribe freeSources
- National Cyber Security Centre, “Helping small businesses with free, hands-on cyber consultancy”, blog, 15 July 2026. https://www.ncsc.gov.uk/blogs/helping-small-businesses-with-free-hands-on-cyber-consultancy
- Department for Science, Innovation and Technology and Home Office, “Cyber security breaches survey 2025/2026”, official statistics, 30 April 2026. https://www.gov.uk/government/statistics/cyber-security-breaches-survey-20252026/cyber-security-breaches-survey-20252026
- Department for Business and Trade, “Business population estimates for the UK and regions 2025: statistical release”, 2 October 2025. https://www.gov.uk/government/statistics/business-population-estimates-2025/business-population-estimates-for-the-uk-and-regions-2025-statistical-release




